How bitcoin cold wallets lost $70 million in an attack that never touched the devices

Lời nói đầu:The Coldcard wallet-drain attack runs entirely on the attacker's machine; the victim's device is not involved and could be powered off anywhere. Victims span three address formats, revealing systematic enumeration of candidate seeds across every derivation path, not targeted attacks. Galaxy warns more waves are likely if owners don't move funds, but there is no test an owner can run to determine exposure. Affected firmware includes Coldcard Mk3, with Block adding Mk2, Mk4, Q, and Mk5; newer devices are unaffected. One mistake: the attacker used a paid account at a known blockchain data provider, and its logs matched the suspected sweep workflow with extraordinary specificity.

Every step of that runs on the attacker's machine. The victim's device is not involved at any point and could be powered off in a safe on another continent.

Galaxy's breakdown shows the process running. Of the drained wallets, 1,183 used the modern native segwit address format, seven used an older standard and six an older one still. Nobody targets a specific victim across three address formats at once.

That is systematic enumeration, checking each candidate seed against every path it might have produced. The operator can widen the search, refine it and return whenever they choose.

Galaxy warned further waves are likely if owners do not move their funds.

The victims span three address formats, which is what a scanner looks like. (Shaurya Malwa/CoinDesk)

Nor can an owner determine whether they are exposed. There is no test to run against your own wallet that reveals whether your seed sits inside the reproducible range.

Attack might not be fully finished

Coinkite, Coldcard's maker, has warned Mk3 owners and says its newer devices are unaffected, while Block's report places the Mk2, Mk4, Q and Mk5 in scope as well. Until that is resolved, anyone who generated a seed on the affected firmware has to assume the worst rather than verify it.

The attacker did make one mistake, however.

Block's Clay Garrett said on X that the operator used a paid account at a “well-known blockchain data provider” to query the source addresses during the sweeps, and that the provider's internal logs matched the suspected workflow with what he called extraordinary specificity, down to the number, timing and sequence of requests.

Miễn trừ trách nhiệm

Các ý kiến ​​trong bài viết này chỉ thể hiện quan điểm cá nhân của tác giả và không phải lời khuyên đầu tư. Thông tin trong bài viết mang tính tham khảo và không đảm bảo tính chính xác tuyệt đối. Nền tảng không chịu trách nhiệm cho bất kỳ quyết định đầu tư nào được đưa ra dựa trên nội dung này.
Bài viết trước

Sau 3 lần bỏ lỡ kỳ vọng lợi nhuận, Phố Wall vẫn chưa từ bỏ cổ phiếu Coinbase

Bài tiếp theo

Ngân hàng Trung ương Nga cho phép nhà đầu tư nhỏ lẻ tiếp cận Crypto